漏洞描述
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin.' While all APIs and authentication middleware are developed based on framework `droplet`, some API directly use the interface of framework `gin` thus bypassing their authentication.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
apisix.apache.orghttps://apisix.apache.org/zh/blog/2021/12/28/dashboard-cve-2021-45232/↗github.comhttps://github.com/pingpongcult/CVE-2021-45232↗github.comhttps://github.com/advisories/GHSA-wcxq-f256-53xp↗twitter.comhttps://twitter.com/403Timeout/status/1475715079173976066↗github.comhttps://github.com/wuppp/cve-2021-45232-exp↗